Remote AWS Cloud Security Engineer - FedRAMP & Zero Trust

Peraton

United States

Remote

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Peraton seeks an experienced AWS Cloud Security Engineer to design, build, and operate security controls for a FedRAMP Moderate AWS cloud infrastructure supporting the RDG program. This hands-on role embeds secure-by-design principles in cloud architecture and ensures ongoing FedRAMP compliance.

The engineer will implement security architecture, harden cloud environments, and support ATO activities within a federal compliance framework. This is a 100% remote position.

Qualifications

  • US citizenship is required and ability to obtain Top-Secret eligible clearance.
  • Minimum 8 years of relevant work experience in computer science or related field.
  • 5+ years of hands-on AWS engineering experience with 3+ years in cloud security roles.
  • Experience with FedRAMP Moderate/High, DoD RMF, or comparable federal security controls.
  • Experience supporting SSPs and RMF processes, and AWS GovCloud (US) environments.
  • Hands-on AWS security services including IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager.
  • Strong knowledge of NIST SP 800-53 rev 5 controls and mapping implementations to controls.
  • 3+ years with IaC (Terraform/CloudFormation) and policy-as-code tooling.
  • Networking security fundamentals (VPC, SGs, NACLs, PrivateLink, TGW).
  • Experience with vulnerability management tools and remediation tracking.
  • Experience implementing Zero Trust Architecture in AWS.
  • Familiarity with SIEM/log aggregation tools (Splunk, OpenSearch, CloudWatch).
  • Scripting in Python or Bash for automation.
  • Understanding encryption standards (FIPS 140-2/140-3, TLS 1.2+).
  • One of: AWS Security – Specialty, AWS SA – Security, CISSP, CISM, or Security+.

Responsibilities

  • Design and implement security architecture for AWS workloads aligned with FedRAMP Moderate baseline controls.
  • Build and maintain security guardrails using AWS-native services (IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF, Macie, Inspector).
  • Implement and manage IaC security controls (Terraform/CloudFormation) with policy as code.
  • Support System Security Plans (SSPs), ATO activities, and POA&M remediation.
  • Perform continuous monitoring, vulnerability scanning, patch management tracking, and monthly/annual assessment support.
  • Configure and maintain centralized logging, SIEM integration, and audit trail retention per FedRAMP/NIST requirements.
  • Implement least-privilege IAM policies, SCPs, and cross-account access controls.
  • Manage encryption at rest and in transit (KMS, ACM, TLS) per FIPS 140-2/140-3 requirements.
  • Respond to security incidents, perform root cause analysis, and support incident response playbooks.
  • Collaborate with DevOps/Platform teams to embed security into CI/CD pipelines (DevSecOps).
  • Maintain documentation for control implementation statements, architecture diagrams, and audit evidence.
  • Support boundary definition and system categorization activities (FIPS 199).

Skills

AWS security engineering
FedRAMP/NIST compliance
Zero Trust Architecture
Vulnerability management
SIEM/log management
Scripting (Python/Bash)
Encryption standards
Cloud security architecture
Incident response

Education

Bachelor's degree in Computer Science / Cybersecurity / Information Technology
AWS Certified Security – Specialty
CISSP / CISM / Security+

Tools

Terraform
CloudFormation
AWS IAM
GuardDuty
Security Hub
Config
KMS
WAF
Macie
Inspector
OpenSearch
Splunk

Job description

Peraton seeks an experienced AWS Cloud Security Engineer to design, build, and operate security controls for a FedRAMP Moderate AWS cloud infrastructure supporting the RDG program. This hands-on role embeds secure-by-design principles in cloud architecture and ensures ongoing FedRAMP compliance.

The engineer will implement security architecture, harden cloud environments, and support ATO activities within a federal compliance framework. This is a 100% remote position.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote AWS Cloud Security Engineer - FedRAMP Ready
Remote AWS Cloud Security Engineer - FedRAMP Ready

Peraton • Northern (KY)

Hybrid
USD 104,000 - 166,000
100% remote
AWS Cloud Security Engineer
AWS Cloud Security Engineer

Peraton • United States

Remote
USD 120,000 - 180,000
Remote FedRAMP Security Engineer - Cloud Compliance & Risk
Remote FedRAMP Security Engineer - Cloud Compliance & Risk

Jobgether SRL • United States

On-site
USD 140,000 - 155,000
Fully remote within the United States
Health coverage
401(k) matching
+1
Cloud Security Architect
Cloud Security Architect

Pipe Recruit • Palo Alto (CA)

On-site
USD 207,000 - 344,000
Cloud Security Engineer - DoD/FedRAMP & Zero Trust Expert
Cloud Security Engineer - DoD/FedRAMP & Zero Trust Expert

Talentify • Town of Florida (NY)

On-site
USD 110,000 - 165,000
Competitive salary
Health benefits
Retirement plan
+1
FedRAMP Cloud Security Architect — Remote Eligible
FedRAMP Cloud Security Architect — Remote Eligible

Pipe Recruit • Palo Alto (CA)

Hybrid
USD 207,000 - 344,000
External Job Posting Title AWS Cloud Security Engineer
External Job Posting Title AWS Cloud Security Engineer

Peraton • Northern (KY)

Hybrid
USD 104,000 - 166,000
100% remote
Remote Senior DevSecOps Engineer — Cloud & Security
Remote Senior DevSecOps Engineer — Cloud & Security

Peraton • Reston (VA)

On-site
USD 135,000 - 216,000
Senior SecDevOps Engineer - Secure Multi-Cloud (FedRAMP)
Senior SecDevOps Engineer - Secure Multi-Cloud (FedRAMP)

The Phoenix Group • Arlington (VA)

On-site
USD 120,000 - 190,000
Remote Cloud Security Engineer - AWS & Zero-Trust Automation
Remote Cloud Security Engineer - AWS & Zero-Trust Automation

Smithspektrum • United States

On-site
USD 170,000 - 220,000
Equity participation
Fully remote position
4 weeks PTO
+2